<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Secondlife.com hacked &#8211; full access to all customer data</title>
	<atom:link href="http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/</link>
	<description></description>
	<lastBuildDate>Sat, 17 Sep 2011 10:00:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Andutzica</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-5103</link>
		<dc:creator>Andutzica</dc:creator>
		<pubDate>Fri, 27 Nov 2009 11:58:03 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-5103</guid>
		<description>auzi unu baga IDul meu de yahoo in lista ta ca vreau sa te intreb cv.....ID uzumaki.anda@yahoo.com</description>
		<content:encoded><![CDATA[<p>auzi unu baga IDul meu de yahoo in lista ta ca vreau sa te intreb cv&#8230;..ID <a href="mailto:uzumaki.anda@yahoo.com">uzumaki.anda@yahoo.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KaBaDaYi</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-1152</link>
		<dc:creator>KaBaDaYi</dc:creator>
		<pubDate>Sat, 21 Feb 2009 09:57:45 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-1152</guid>
		<description>Lol concat function 

select * from yoneticiler where (user=&#039;&#039; and pass=md5(&#039;&#039;)) or (user=&#039;bG9jYXRpb246aHR0cDov&#039; and &#039;bG9jYXRpb246aHR0cDov&#039;=concat(&#039;bG9jYXRp&#039;,&#039;b246aHR0cDov&#039;))</description>
		<content:encoded><![CDATA[<p>Lol concat function </p>
<p>select * from yoneticiler where (user=&#8221; and pass=md5(&#8221;)) or (user=&#8217;bG9jYXRpb246aHR0cDov&#8217; and &#8216;bG9jYXRpb246aHR0cDov&#8217;=concat(&#8216;bG9jYXRp&#8217;,'b246aHR0cDov&#8217;))</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shocker</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-957</link>
		<dc:creator>Shocker</dc:creator>
		<pubDate>Thu, 12 Feb 2009 19:35:23 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-957</guid>
		<description>@Zorba &amp; @gigix: aveti meniul &quot;Categories&quot;, use it.</description>
		<content:encoded><![CDATA[<p>@Zorba &#038; @gigix: aveti meniul &#8220;Categories&#8221;, use it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Second Life is also victim of SQL Injection &#124; N-Stalker Web Security Community</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-949</link>
		<dc:creator>Second Life is also victim of SQL Injection &#124; N-Stalker Web Security Community</dc:creator>
		<pubDate>Thu, 12 Feb 2009 14:56:59 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-949</guid>
		<description>[...] to Hacker&#8217;s Blog, the famous virtual world &#8220;Second Life&#8221; was susceptible to a SQL injection [...]</description>
		<content:encoded><![CDATA[<p>[...] to Hacker&#8217;s Blog, the famous virtual world &#8220;Second Life&#8221; was susceptible to a SQL injection [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abu Bakr</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-876</link>
		<dc:creator>Abu Bakr</dc:creator>
		<pubDate>Wed, 11 Feb 2009 17:34:44 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-876</guid>
		<description>haha lol great !!</description>
		<content:encoded><![CDATA[<p>haha lol great !!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Viana</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-796</link>
		<dc:creator>Viana</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:43:21 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-796</guid>
		<description>second life fail =/</description>
		<content:encoded><![CDATA[<p>second life fail =/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gigix</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-791</link>
		<dc:creator>gigix</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:28:05 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-791</guid>
		<description>exista vreo vulnerabilitate prezenta aici care sa fie pe altceva decat lipsa fortarii unui parametru in integer?</description>
		<content:encoded><![CDATA[<p>exista vreo vulnerabilitate prezenta aici care sa fie pe altceva decat lipsa fortarii unui parametru in integer?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zorba</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-785</link>
		<dc:creator>Zorba</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:04:37 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-785</guid>
		<description>sa = sau</description>
		<content:encoded><![CDATA[<p>sa = sau</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zorba</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-784</link>
		<dc:creator>Zorba</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:03:13 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-784</guid>
		<description>Ha ha, daca te bazezi pe responsabilitatea programatorului, atunci 99% sa mai mult din site-uri sunt vulnerabile. Dar as vrea sa vad si alte hack-uri, nu doar sql injection in site-uri php pe pagina de search sa alte pagini care listeaza date pe baza unui parametru in query string.</description>
		<content:encoded><![CDATA[<p>Ha ha, daca te bazezi pe responsabilitatea programatorului, atunci 99% sa mai mult din site-uri sunt vulnerabile. Dar as vrea sa vad si alte hack-uri, nu doar sql injection in site-uri php pe pagina de search sa alte pagini care listeaza date pe baza unui parametru in query string.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian</title>
		<link>http://blog.rstcenter.com/2009/02/10/secondlifecom-hacked-full-access-to-all-customer-data/comment-page-1/#comment-778</link>
		<dc:creator>Adrian</dc:creator>
		<pubDate>Tue, 10 Feb 2009 17:35:16 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=1198#comment-778</guid>
		<description>@Zorba

Sunt si situri scrise in ASP .Net vulnerabile la SQL Injection. 
Daca scrii ceva de genu 
string query = &quot;select * from users where login = &quot; + login
atunci inviti oamenii la SQL injection.

E vorba de responsabilitatea programatorului, nu conteaza tehnologia care o folosesti.</description>
		<content:encoded><![CDATA[<p>@Zorba</p>
<p>Sunt si situri scrise in ASP .Net vulnerabile la SQL Injection.<br />
Daca scrii ceva de genu<br />
string query = &#8220;select * from users where login = &#8221; + login<br />
atunci inviti oamenii la SQL injection.</p>
<p>E vorba de responsabilitatea programatorului, nu conteaza tehnologia care o folosesti.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

